YuukioFuyu / Inventaris-Barang

Sistem Inventarisasi Barang Berbasis Web
MIT License
4 stars 0 forks source link

Vulnerability report #1

Open JafarAkhondali opened 3 months ago

JafarAkhondali commented 3 months ago

We are a group of researchers from Leiden University, and we conduct research on vulnerabilities in open-source software. We have discovered and verified a high-severity vulnerability in your project(YuukioFuyu/Inventaris-Barang). Explaining the vulnerability further in this issue could allow malicious users to access details, so we recommend enabling private vulnerability reporting on GitHub to discuss this matter confidentially. After you have enabled this feature, please add a comment to this issue so we can continue our discussion. If you have any questions, feel free to leave a reply here or send an email to: j.akhoundali [at] liacs.leidenuniv.nl

YuukioFuyu commented 3 months ago

Thank you for reaching out and bringing this to our attention. We understand the concern about publicly discussing the vulnerability details. I'm happy to confirm that I've enabled private vulnerability reporting on this repository. Please feel free to share the specifics of the vulnerability through that private channel. We can then discuss the next steps for addressing it securely. Thanks again for your attention.